Skip to content

Commit bdd0802

Browse files
authored
Acrolinx fixes
1 parent 6fd1643 commit bdd0802

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

articles/defender-for-cloud/alerts-reference.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -324,7 +324,7 @@ Microsoft Defender for Containers provides security alerts on the cluster level
324324

325325
<sup><a name="footnote1"></a>1</sup>: **Preview for non-AKS clusters**: This alert is generally available for AKS clusters, but it is in preview for other environments, such as Azure Arc, EKS and GKE.
326326

327-
<sup><a name="footnote2"></a>2</sup>: **Limitations on GKE clusters**: GKE uses a Kuberenetes audit policy that doesn't support all alert types. As a result, this security alert, which is based on Kubernetes audit events, is not supported for GKE clusters.
327+
<sup><a name="footnote2"></a>2</sup>: **Limitations on GKE clusters**: GKE uses a Kubernetes audit policy that doesn't support all alert types. As a result, this security alert, which is based on Kubernetes audit events, is not supported for GKE clusters.
328328

329329
<sup><a name="footnote3"></a>3</sup>: This alert is supported on Windows nodes/containers.
330330

@@ -686,7 +686,7 @@ VM.Windows_CommandLineStartingAllExe | Detected suspicious command line used to
686686
VM.Windows_DisablingAndDeletingIISLogFiles | Detected actions indicative of disabling and deleting IIS log files | Medium
687687
VM.Windows_DownloadUsingCertutil | Suspicious download using Certutil detected | Medium
688688
VM.Windows_EchoOverPipeOnLocalhost | Detected suspicious named pipe communications | High
689-
VM.Windows_EchoToConstructPowerShellScript | Dynamic PS script construction | Medium
689+
VM.Windows_EchoToConstructPowerShellScript | Dynamic PowerShell script construction | Medium
690690
VM.Windows_ExecutableDecodedUsingCertutil | Detected decoding of an executable using built-in certutil.exe tool | Medium
691691
VM.Windows_FileDeletionIsSospisiousLocation | Suspicious file deletion detected | Medium
692692
VM.Windows_KerberosGoldenTicketAttack | Suspected Kerberos Golden Ticket attack parameters observed | Medium
@@ -703,7 +703,7 @@ VM.Windows_PowerShellPowerSploitScriptExecution | Suspicious PowerShell cmdlets
703703
VM.Windows_RansomwareIndication | Ransomware indicators detected | High
704704
VM.Windows_SqlDumperUsedSuspiciously | Possible credential dumping detected [seen multiple times] | Medium
705705
VM.Windows_StopCriticalServices | Detected the disabling of critical services | Medium
706-
VM.Windows_SubvertingAccessibilityBinary | Sticky keys attack detected <br/> Suspicious account creation detcted Medium
706+
VM.Windows_SubvertingAccessibilityBinary | Sticky keys attack detected <br/> Suspicious account creation detected Medium
707707
VM.Windows_SuspiciousFirewallRuleAdded | Detected suspicious new firewall rule | Medium
708708
VM.Windows_SuspiciousFTPSSwitchUsage | Detected suspicious use of FTP -s switch | Medium
709709
VM.Windows_SuspiciousSQLActivity | Suspicious SQL activity | Medium
@@ -720,7 +720,7 @@ VM_MaliciousSQLActivity | Malicious SQL activity | High
720720
VM_ProcessWithDoubleExtensionExecution | Suspicious double extension file executed | High
721721
VM_RegistryPersistencyKey | Windows registry persistence method detected | Low
722722
VM_ShadowCopyDeletion | Suspicious Volume Shadow Copy Activity <br/> Executable found running from a suspicious location | High
723-
VM_SuspectExecutablePath | Executable found running from a suspicious location <br/> Detected anomoalous mix of uppercase and lowercase characters in command line | Informational <br/> <br/> Medium <br/> |
723+
VM_SuspectExecutablePath | Executable found running from a suspicious location <br/> Detected anomalous mix of uppercase and lowercase characters in command line | Informational <br/> <br/> Medium <br/> |
724724
VM_SuspectPhp | Suspicious PHP execution detected | Medium
725725
VM_SuspiciousCommandLineExecution | Suspicious command execution | High
726726
VM_SuspiciousScreenSaverExecution | Suspicious Screensaver process executed | Medium

0 commit comments

Comments
 (0)